this doesn't make any sense, most vulnerability you find on products are "game over" vulnerabilities. It's common. If you would give a billion dollars to every such findings in an audit then you would be pretty quickly calling bankruptcy.
Also, I can personally live for a year on that kind of money. But that's another issue.
On the other hand, that is maybe what they would have payed for a real audit of a few days/weeks and it's not even sure the vulnerability would have been found (especially considering the size of Facebook). So yeah maybe they also deserve more.
David is right about this, too. A $50,000 pentest of any major web property is likely to find multiple sev:hi vulnerabilities. By the logic the grandparent comment uses, those audits should cost more like $1.5MM.
Also, I can personally live for a year on that kind of money. But that's another issue.
On the other hand, that is maybe what they would have payed for a real audit of a few days/weeks and it's not even sure the vulnerability would have been found (especially considering the size of Facebook). So yeah maybe they also deserve more.
I'm mixed.